Cookie Policy
1. What Are Cookies?
Cookies are small text files placed on your device (computer, tablet, or phone) by a website when you visit. They are widely used to make websites work correctly, to remember your preferences, and to provide information to the website owner about how visitors interact with the site.
In addition to traditional cookies, we may use similar tracking technologies including web beacons (pixel tags), local storage, and session storage. This policy covers all such technologies.
2. Cookies We Use
We use the following categories of cookies:
2.1 Strictly Necessary Cookies
These cookies are essential for the website to function and cannot be disabled. They do not collect personal data for marketing purposes. You can block them in your browser settings, but the site will not function correctly without them.
wordpress_logged_in_[hash] — WordPress login session. Authenticates logged-in users. Duration: session / persistent based on “Remember Me.” First-party.
wordpress_sec_[hash] — WordPress security cookie. Used by the admin area. Duration: session. First-party.
woocommerce_cart_hash / woocommerce_items_in_cart — WooCommerce shopping cart. Tracks cart contents. Duration: session. First-party.
wp_woocommerce_session_[hash] — WooCommerce session data including cart, order status, and customer preferences. Duration: 2 days. First-party.
PHPSESSID — PHP server session ID. Required for Patreon OAuth state management (CSRF protection) and authenticated content gating. Stored as HttpOnly, Secure cookie. Duration: session. First-party.
2.2 Functional Cookies
These cookies remember your preferences to enhance your experience. You can opt out of these without losing core website functionality.
woocommerce_recently_viewed — Remembers recently viewed products. Duration: session. First-party.
wp-settings-[user_id] / wp-settings-time-[user_id] — Stores WordPress display preferences for logged-in users. Duration: 1 year. First-party.
2.3 Analytics Cookies
These help us understand how visitors interact with our site so we can improve it. We use Google Analytics with IP anonymisation enabled. No personally identifiable information is passed to Google Analytics.
_ga — Google Analytics. Distinguishes unique users by assigning a randomly generated number as a client identifier. Duration: 2 years. Third-party (Google Ireland Ltd).
_ga_[container_id] — Google Analytics 4. Stores and counts page views. Duration: 2 years. Third-party.
_gid — Google Analytics. Distinguishes users. Duration: 24 hours. Third-party.
You can opt out of Google Analytics across all websites by installing the Google Analytics Opt-out Browser Add-on.
2.4 Patreon OAuth Session Storage
When you authenticate via “Sign in with Patreon,” we maintain your authenticated state using a server-side PHP session referenced by a secure, HttpOnly session cookie. No Patreon access tokens are stored in browser cookies or localStorage. All token storage is server-side and encrypted. This is strictly necessary for the Patreon content gating functionality.
3. Third-Party Cookies
Third-party cookies may be set by services we embed or link to. We do not control these cookies. The main third parties that may set cookies when you use our site:
- Google (Google Analytics, Google Fonts): Google Privacy Policy
- PayPal: Set on checkout pages if PayPal is selected. PayPal Privacy Policy
- Stripe: Set during payment processing. Stripe Privacy Policy
- Patreon: Set on Patreon’s own pages during OAuth authentication. Patreon Privacy Policy
4. Your Consent and Cookie Choices
EEA and UK Visitors (GDPR / ePrivacy)
When you first visit our site from an EEA or UK IP address, we will present a cookie consent notice. You may accept all cookies, accept only necessary cookies, or customise your preferences. You can change your consent choices at any time by clicking “Cookie Preferences” in our website footer.
Strictly necessary cookies do not require consent and cannot be disabled via our consent tool (they can be blocked in your browser, which will break site functionality).
California Visitors (CCPA)
We do not “sell” or “share” cookie data for cross-context behavioural advertising as defined by the CCPA/CPRA. If this changes, we will update this policy and provide an opt-out mechanism. You may also use the Global Privacy Control (GPC) browser signal, which we honour.
All Visitors — Browser-Level Controls
You can manage cookies through your browser settings. Links to instructions for common browsers:
Note that blocking cookies may affect your ability to use the shopping cart, stay logged in, or access Patreon-gated content.
5. Data Collected via Cookies
Cookies on our site may collect: session identifiers; anonymised user identifiers; pages visited and time spent; referring URL; browser and device type; cart contents; and login state. They do not collect payment card data, passwords, or unanonymised health information.
6. Changes to This Policy
We may update this Cookie Policy to reflect changes in technologies or regulations. The “Effective Date” at the top of this page will reflect the date of any revision. We will notify EEA/UK users of material changes through our cookie consent tool.
7. Contact
Cookie and Tracking Enquiries
Email: privacy@grimmsapothecary.net
Grimm’s Apothecary LLC · Port Jervis, New York